Damn Vulnerable NodeJS Application by Appsecco: an Express and MySQL application that demonstrates the OWASP Top 10 (2017) in Node.js, from command and SQL injection to XXE, insecure deserialization and broken access control, with a guide for exploiting and fixing each flaw.
Not startedDockercommit 234b22fx86_64 · aarch64Secret
Exploit each OWASP Top 10 vulnerability listed on the Learn page.
The brief for this lab lives in its repository.